{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74715","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.928Z","datePublished":"2026-08-22T15:33:10.262Z","dateUpdated":"2026-08-25T05:41:58.565Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-25T05:41:58.565Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix netns reference imbalance in conntrack kfuncs\n\nThe opts argument of the BPF conntrack kfuncs can point to a shared\nmap value.  __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read\nopts->netns_id separately when acquiring and releasing the network\nnamespace reference.\n\nThe reference imbalance can occur as follows:\n\n  CPU 0                                  CPU 1\n  read opts->netns_id (-1)\n  skip get_net_ns_by_id()\n                                         write opts->netns_id (id)\n  read opts->netns_id (id)\n  put_net(net) /* no matching get */\n\nThe reverse transition leaks the reference.  Repeating the unmatched put\ncan destroy a live namespace and crash later users.\n\nThe kernel reported:\n\n  Oops: general protection fault, probably for non-canonical address\n  KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef]\n  RIP: 0010:bpf_prog_test_run_xdp+0x52c/0x1700\n  Call Trace:\n   __sys_bpf+0x1662/0x50c0\n   __x64_sys_bpf+0x73/0xb0\n   do_syscall_64+0xf9/0x540\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  Kernel panic - not syncing: Fatal exception\n\nSnapshot every input field of opts with READ_ONCE() before validating or\nusing it.  The netns_id snapshot keeps the namespace get/put pair\nbalanced, while the other snapshots keep the remaining options from\nchanging partway through an invocation.  The individual reads can still\nobserve an inconsistent combination during a concurrent update, but each\nselected field value remains stable for that invocation."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in BPF conntrack kfuncs reached only via the bpf() syscall (load, BPF_PROG_TEST_RUN, or attached XDP/TC programs), not from remote packet handling alone; kernel guidance classifies BPF as Local.\nAC:L - Exploitation needs a race on opts->netns_id in a shared BPF map value, but the attacker authors the program, drives concurrent bpf_map_update_elem and kfunc calls, and can pin threads to different CPUs to win the race reliably.\nPR:L - Triggering bpf_xdp_ct_lookup/bpf_skb_ct_lookup requires loading XDP or TC-BPF programs, which needs CAP_BPF and CAP_NET_ADMIN; both are obtainable by an unprivileged user inside a user/network namespace via unshare.\nUI:N - No victim interaction is required; the attacker loads their own BPF program, supplies map-backed opts, and runs concurrent test-run or traffic to trigger the refcount imbalance themselves.\nS:U - Impact is premature destruction of a live network namespace and kernel crashes within the same kernel security domain; it does not cross a VM, container-to-host, or IOMMU boundary.\nC:H - Repeated unmatched put_net() can drop a live namespace refcount to zero and free it while still in use, creating a net-namespace use-after-free that can expose freed kernel memory and enable information disclosure.\nI:H - The refcount corruption can destroy active network namespaces and corrupt kernel networking state; such lifetime bugs are memory corruption primitives that can be leveraged for arbitrary kernel modification or control-flow hijacking.\nA:H - The fix commit documents a reproduced general protection fault and kernel panic in bpf_prog_test_run_xdp from a null-ptr-deref after the namespace is destroyed, confirming complete system availability loss."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nf_conntrack_bpf.c"],"versions":[{"version":"aed8ee7feb44b6537af1e0b4f03365d42928be38","lessThan":"e5e060eb63d10b41ab60fd955649479d99b38210","status":"affected","versionType":"git"},{"version":"aed8ee7feb44b6537af1e0b4f03365d42928be38","lessThan":"fdeba03fea78407a8c52faa99177c9f7f29f90eb","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nf_conntrack_bpf.c"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.1.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e5e060eb63d10b41ab60fd955649479d99b38210"},{"url":"https://git.kernel.org/stable/c/fdeba03fea78407a8c52faa99177c9f7f29f90eb"}],"title":"bpf: Fix netns reference imbalance in conntrack kfuncs","x_generator":{"engine":"bippy-1.2.0"}}}}